If you know the mac address then follow below steps,
1) Create the policy
wm3400-34710C8(config)#association-acl-policy
2) Deny or allow the specific mac address
![d5aa9fde09f845eab3688af5608b734e_RackMultipart20140621-18626-11ubg3v-Untitled_inline.png d5aa9fde09f845eab3688af5608b734e_RackMultipart20140621-18626-11ubg3v-Untitled_inline.png](/t5/image/serverpage/image-id/5824iEE8904ADF4FC66FA/image-size/large?v=v2&px=999)
deny 11-22-33-44-56-01 11-22-33-44-56-01 precedence 160
permit 11-22-33-44-66-01 11-22-33-44-66-FF precedence 170
3) Apply the policy to specific vlan or WLAN.